On Thu, Aug 14, 2025 at 12:01:33PM -0700, Otto Kekäläinen wrote:
The git-buildpackage config includes these two attributes:
- upstream-vcs-tag

I agree this would be useful to support as an upstream metadata field.
- upstream-signatures

This seems to be more of a git workflow policy rather than an upstream metadata 
field.
If upstream signs releases, the presence of a debian/upstream/signing-key.asc
and configuration in debian/watch (pgpsigmangle) indicates whether the presence
of the signature is mandatory. I'm also hesitant of bringing information
about the upstream *tarball* into debian/upstream/metadata, as that is a role
debian/watch already plays.

(Maybe you mean signing of upstream tags rather than upstream tarballs? That is
not what "upstream-signatures" in git-buildpackage appears to be about based
on my reading of 
https://salsa.debian.org/debian/dh-make/-/blob/master/lib/debian/gbp.conf.ex)

Cheers,

Jelmer

Reply via email to